HackerOne Disclosed Reports - 2026-08-29

0 Replies, 10 Views

Logo
High
resolved

**Unauthenticated IDOR allows modification of payment customer billing information**


Bug reported by Vision KC was disclosed at August 30, 2026, 4:54 am   |   Insecure Direct Object Reference (IDOR)

The application contained an access control issue in the payment billing information edit functionality. An unauthenticated user was able to access the payment edit endpoint and modify the billing information associated with a payment without any authorization check. The issue occurred because the application allowed access to the edit page using only the payment identifier in the URL, and the server did not verify whether the requester was logged in or had permission to modify the customer information linked to that payment.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)